the Vulnerability exPerienCe 19
data due to failure to remediate a critical, published vulnerability. I
can see the tort lawyers circling!
California Civil Code § 1798.84 specifies considerable penalties
for companies doing business with California residents when those
companies fail to notify the victims of a security breach within a cer-
tain period of time. e damage from such disclosure could be large
but so could the civil penalties. e legislation is only one example of
a growing trend towards punishing companies responsible for data
breaches regardless of their physical location because they do business
with local residents.
2.4.4 Loss of Revenue
A more direct loss, that of revenue or potential revenue, is of major
concern in any bus